EcoStruxure PME 9.0 IT Guide Overview
EcoStruxure PME 9.0 IT Guide Overview
Electrical equipment should be installed, operated, serviced and maintained only by qualified
personnel. No responsibility is assumed by Schneider Electric for any consequences arising out of
the use of this material.
As standards, specifications and designs change from time to time, please ask for confirmation of
the information given in this publication.
Safety Information
Important Information
Read these instructions carefully and look at the equipment to become familiar with the
device before trying to install, operate, service or maintain it. The following special
messages may appear throughout this bulletin or on the equipment to warn of potential
hazards or to call attention to information that clarifies or simplifies a procedure.
DANGER
DANGER indicates a hazardous situation which, if not avoided, will result in death or serious
injury.
WARNING
WARNING indicates a hazardous situation which, if not avoided, could result in death or
serious injury.
CAUTION
CAUTION indicates a hazardous situation which, if not avoided, could result in minor or
moderate injury.
NOTICE
NOTICE is used to address practices not related to physical injury.
Please Note
Electrical equipment should be installed, operated, serviced and maintained only by qualified
personnel. No responsibility is assumed by Schneider Electric for any consequences arising out of
the use of this material.
A qualified person is one who has skills and knowledge related to the construction, installation, and
operation of electrical equipment and has received safety training to recognize and avoid the
hazards involved.
Contents
Safety Precautions 6
Introduction 7
Resources 8
Overview 10
System Architecture 11
Client Types 13
Engineering Client 13
Web Client 13
Licensing 15
License Activation 15
License Types 15
System backups 18
IT Requirements 20
Computer Hardware 21
Choosing Computer Type, CPU, and RAM 21
Choosing Hard Disk Drives (HDDs) 23
Operating Environment 27
Windows Updates 28
Localization 28
Operating System Considerations 28
SQL Server Considerations 29
Network Connectivity 31
Network Communication 31
Network Shares 31
Windows Domain Compatibility 31
IPv6 Compatibility 31
IP Port Requirements 31
Device Networks 34
Device networks overview 35
Network Types 36
Network Performance 37
Time synchronization 38
Tools 39
Other IT Considerations 40
PME Server Name Limitations 40
Display Resolution 40
Cybersecurity 41
Planning 41
Network security 41
Data encryption 41
Malware detection 41
7EN42-0168-00 Page4
IT Guide
Page 5 7EN42-0168-00
IT Guide Safety Precautions
Safety Precautions
During installation or use of this software, pay attention to all safety messages that occur in the
software and that are included in the documentation. The following safety messages apply to this
software in its entirety.
WARNING
UNINTENDED EQUIPMENT OPERATION
• Do not use the software or devices for critical control or protection applications where human
or equipment safety relies on the operation of the control action.
• Do not use the software to control time-critical functions.
• Do not use the software to control remote equipment without proper access control and status
feedback.
Failure to follow these instructions can result in death, serious injury, or equipment
damage.
WARNING
INACCURATE DATA RESULTS
• Do not incorrectly configure the software or the devices.
• Do not base your maintenance or service actions solely on messages and information
displayed by the software.
• Do not rely solely on software messages and reports to determine if the system is functioning
correctly or meeting all applicable standards and requirements.
• Consider the implications of unanticipated transmission delays or failures of communications
links.
Failure to follow these instructions can result in death, serious injury, equipment
damage, or permanent loss of data.
WARNING
POTENTIAL COMPROMISE OF SYSTEM AVAILABILITY, INTEGRITY, AND
CONFIDENTIALITY
Use cybersecurity best practices to help prevent unauthorized access to the software.
Failure to follow these instructions can result in death, serious injury, equipment
damage, or permanent loss of data.
Work with facility IT System Administrators to ensure that the system adheres to the site-specific
cybersecurity policies.
7EN42-0168-00 Page 6
Introduction IT Guide
Introduction
Power Monitoring Expert (PME) is a client-server, on-premise software application that collects
power monitoring data through a network of connected devices. The power monitoring data is
processed and stored using Microsoft SQL Server and can be accessed by users in a variety of
formats through different user interfaces.
This document is intended for IT professionals who support the PME system installation. It provides
information on possible deployment architectures, supported operating environments, required
access permissions, IT and device network considerations, cybersecurity, the PME installer, as
well as general dependencies and prerequisites.
Page 7 7EN42-0168-00
IT Guide Introduction
Resources
Download Center
NOTE: The EcoStruxure™Power Monitoring Expert System Guide includes the content of the
following guides: What's New Guide, IT Guide, Web Applications Guide, and the OR Isolated
Power Interface User Guide.
The following EcoStruxure™Power Monitoring Expert9.0 documents are available on the Schneider
Electric Download Center:
Exchange Extranet
Other
7EN42-0168-00 Page 8
Introduction IT Guide
Technical Support
[Global contact information. Contact a Software Registration Center (SRC) if you exceed the
license return limit, or if a license has become untrusted. Do not contact a SRC for
troubleshooting license issues or to get new licenses. They are not able to help with these
issues.]
External Resources
l How to choose antivirus software to run on computers that are running SQL Server
l How to determine which versions and service pack levels of the Microsoft .NET Framework are
installed
Page 9 7EN42-0168-00
IT Guide Overview
Overview
This section provides an overview of the PME system.
Use the links below to find the content you are looking for:
System Architecture
Client Types
Licensing
System backups
7EN42-0168-00 Page 10
Overview IT Guide
System Architecture
PME is a client-server, on-premise software application that collects power monitoring data through
a network of connected devices. The power monitoring data is processed and stored using
Microsoft SQL Server and can be accessed by users in a variety of formats through different user
interfaces.
Standalone architecture
In a Standalone architecture, all PME system files, the SQL Server database, and any other tools or
utilities are installed on the same computer. You access the power monitoring data through clients.
The following example diagram shows both architectures in the context of the overall system,
including the monitoring devices:
Page 11 7EN42-0168-00
IT Guide Overview
However, in some cases it might be necessary to use the Distributed Database architecture, such
as:
l Your customer IT requirements do not allow a Microsoft SQL Server to be installed with another
application on the same server.
l The application requires Microsoft SQL Server redundancy with SQL Clustering or other third-
party tools.
l The application requires specific rules for database management, for example SQL jobs, back-
ups, data security,... .
7EN42-0168-00 Page 12
Overview IT Guide
Client Types
In PME you use clients to access the configuration tools and the applications for viewing data.
There are two different types of clients:
Engineering Client
An Engineering Client is an administrative interface in PME that is used to configure and administer
the system. Engineering clients include tools such as the Management Console, Vista, and
Designer.
One Engineering Client is installed, by default, on the PME server. Additional Engineering Clients
can be installed on other computers, for example on a portable notebook computer, that are more
accessible than the server. Engineering Clients require an Engineering Client license.
Web Client
A Web Client is used to view power monitoring information such as real-time data, historical
information, and alarms which are used in day-to-day power management tasks.
Web Clients access the data on the server through a Web browser. No installation is required. Web
Clients can run on any computer on the network. Web Clients require a Web Client license.
Web Clients can access the Web Applications (Dashboards, Diagrams, Trends, Alarms, and
Reports) in PME.
To set up a Web Client, enter the fully qualified domain name of the PME server or its IP address,
followed by /Web into your browser.
Examples:
l [Link]
l [Link]
NOTE: Web is the default root directory. The root directory is configurable and can be changed
during installation.
By default, the first application on the navigation bar in Web Applications opens in the browser. To
specify which application should open first, add one of the following application parameters to the
Web address: (Note that the parameters are case-sensitive.)
#Dashboards, #Diagrams, #Trends, #Alarms, #Reports
Page 13 7EN42-0168-00
IT Guide Overview
NOTE: For cybersecurity and performance reasons, we recommend that you do not use a Web
Client on the PME server computer.
7EN42-0168-00 Page 14
Overview IT Guide
Licensing
PME is a proprietary software that uses licensing to control its use and distribution. The licensing is
enforced through mechanisms that disable certain software functions if no valid license has been
activated.
To use PME, you must purchase software licenses and activate them in the system. The licenses
give you the right to use the software according to the terms and conditions described in the
software End User License Agreement (EULA). The licenses generally do not expire, unless stated
otherwise in the software EULA. PME licenses are per site. If you have multiple sites, you must
purchase licenses for each site. Multi-site, or enterprise licenses are not available.
PME uses a modular licensing structure where different licenses enable different functions in the
software. Some of these functions are optional, others are required. The licenses are cumulative,
meaning that you can add additional licenses to a system, to enable additional functionality.
License Activation
Purchased licenses must be activated either through online or offline methods. An Internet
connection for the PME server is required for online activation. Offline activation must be done from
an alternate Internet-connected computer or smart-phone with Web access.
Licenses are tied to the host computer (physical or virtual). If PME needs to be moved to a new
computer, the licenses must first be returned and then reactivated on the new computer. Licenses
can only be returned and reactivated twice per calendar year.
License Types
The following table shows the different licenses that are available for PME.
Type Description
New system installations include a time limited trial license.
l enables most of the PME features (see Trial license limitations for
details)
l includes client licenses that can only be used on the primary server,
not on a client computer
l remains active until its expiry even if other licenses have been
activated
Page 15 7EN42-0168-00
IT Guide Overview
The Base license includes the use of one Engineering Client and two Web
Clients.
This is a required license. It enables the use of monitoring devices in PME.
The licenses are sold in bundles of 5, 25, 50, 100, 200, unlimited. At least
one license bundle must be activated in the system. The following
licenses exist:
Device license
l Entry DL (for entry-level device types)
l Billing Module
Gadget Pack license l Energy Usage Gadget Pack (included gadgets: Sankey, Pareto,
Aggregated Pareto, Heat Map, Consumption Ranking, Aggregated
Consumption Ranking)
OPC DA Server This is an optional license. It enables the use of the OPC server
license component in PME.
7EN42-0168-00 Page 16
Overview IT Guide
Page 17 7EN42-0168-00
IT Guide Overview
System backups
Database Backups
Backup the PME databases to be able to recover the live databases if they become unusable.
A backup is a copy of a live database, for example ION_Data in PME. By default, PME
automatically backs up its databases on a daily (ION_Network) or weekly (ION_Data and
ApplicationModules) basis, and keeps two backups of each database in the main installation
folder:
...\Schneider Electric\Power Monitoring Expert\Database\Backup
NOTE: Change the folder location if the default location has insufficient free disk space.
You can perform additional, manual backups using standard SQL Server backup procedures.
Database Archives
Archive data from the live ION_Data database to reduce the database size.
An archive is a copy of a subset of data from the live ION_Data database based on a date range and
the type of data (Data Records, Waveforms and Events). When an ION_Data archive is created it
remains attached to the SQL Server database engine so that its data is still accessible to Vista and
Diagrams. However, the data is not available to other applications in the Web Applications
component.
After you have archived the data, you must trim this same data from the ION_Data database to get
the size reduction.
NOTE: When you trim data from an SQL database, the database file size remains unchanged.
However, the database will first fill the new free space before growing the database file size again.
If you want to reduce the database file size, you must shrink the database after trim, using
standard SQL Server tools.
7EN42-0168-00 Page 18
Overview IT Guide
l SQL Server Express is used as the database engine, which has a database size limit of 10 GB.
l SQL Server (Standard or Enterprise edition) is used as the database engine and the ION_Data
database has become so large that query performance is poor.
l There is not enough free hard drive disk space left and a larger disk cannot be installed.
Page 19 7EN42-0168-00
IT Guide IT Requirements
IT Requirements
This section provides information on specifications and requirements related to information
technology (IT) components, such as computer hardware, operating environment, and networking.
Use the links in the table below to find the content you are looking for:
7EN42-0168-00 Page 20
IT Requirements IT Guide
Computer Hardware
The performance of a computer is determined by the following factors:
When choosing the computer hardware for your PME system, you need to consider the following:
NOTE: Undersized computer hardware is a common source of performance issues with PME
systems.
As a starting point for the selection of these components, we are defining two different system
categories, Basic Systems and Advanced Systems. Decide which category best describes your
system needs and then use the information provided in the tables below to define your computer
hardware specifications.
Basic Systems
A basic system is defined by the following characteristics:
l No custom applications
Page 21 7EN42-0168-00
IT Guide IT Requirements
Desktop
Small ≤ 100 ≤5 Intel Core i5 (2 core)
8 GB (RAM)
Workstation
≤ 250 ≤ 10 Intel Xeon W-21xx (4 core)
16 GB (RAM)
Medium
Server
≤ 600 ≤ 10 Intel Xeon E3-12xx (6 core)
24 GB (RAM)
Server
Large ≤ 2500 ≤ 10 Intel Xeon E3-12xx (10 core)
32 GB (RAM)
Advanced Systems
An advanced system is defined by the following characteristics:
l Large scale data exchange with third party systems (for example through OPC or EWS)
7EN42-0168-00 Page 22
IT Requirements IT Guide
Client Computers
Since all the data processing is done on the server, the client computer hardware recommendations
are the same for Basic Systems and Advanced Systems.
l Engineering Client
Intel Core i3 (2 core or better)
4 GB of RAM
l Web Client
2 GHz, Dual Core processor
4 GB of RAM
HDD Size
The HDD must have enough space for the different programs and applications that are running on
the computer. This includes space for the historical data that is recorded by the system and some
free space as a buffer.
The following table shows the estimated HDD space that is required, without the historical data
logs. The estimates are rounded up and allow for updates and system maintenance.
Page 23 7EN42-0168-00
IT Guide IT Requirements
l The .ldf file is typically just 10% of the .mdf size, but occasionally expands to 100% during nor-
mal operation.
l 100% of the .mdf size is required for free space. The tempDB will occasionally expand to 100%
of the total .mdf size, but not at the same time as a backup. If the backups and tempDB are on
different hard drive groups, they each require x1 .mdf in hard drive space.
Unlike the system software, the historical database size is continuously growing. Its size and
growth can be estimated based on the amount of:
Also, the database occasionally grows by 10% to create room for additional measurements. This
growth operation can occur at any time and you need to consider it in the database size
calculations.
NOTE: Use the Database Growth Calculator tool to estimate the database growth for your
system. The tool is available through the Exchange Community. See Resources for link
information.
HDD Configuration
HDDs can be configured as single drives or drive groups. For a small Basic Systems, a single HDD
is sufficient. For all other systems, we recommend that you separate the major components into
different HDD groups.
RAID Systems
In addition to separating the software components into different hard drive groups, redundant arrays
(RAID) can be used to add simple redundancy. In a RAID 1 configuration, one HDD is a complete
copy of a second HDD. If either of the two HDDs stops operating, the other takes over without any
data loss. The faulty HDD can then be replaced to restore the RAID configuration.
7EN42-0168-00 Page 24
IT Requirements IT Guide
Group 0
Component
HDD1 + HDD2
2x OS ü
HD tempDB ü
D MDF ü
LDF ü
Backups ü
Group 0 Group 1
Component HDD1 + HDD3 +
HDD2 HDD4
4x
OS ü
HD
tempDB ü
D
MDF ü
LDF ü
Backups ü
Group 0 Group 1 Group 2
Component
HDD1 + HDD2 HDD3 + HDD4 HDD5 + HDD6
6x OS ü
HD tempDB ü
D MDF ü
LDF ü
Backups ü
Group 0 Group 1 Group 2 Group 3
Component HDD1 + HDD4 +
HDD3 HDD6
HDD2 HDD5
6x
OS ü
HD
tempDB ü
D
MDF ü
LDF ü
Backups ü
Component Group 0 Group 1 Group 2 Group 3
HDD1 + HDD3 + HDD5 + HDD7 +
HDD2 HDD4 HDD6 HDD8
8x
OS ü
HD
tempDB ü
D
MDF ü
LDF ü
Backups ü
NOTE: Plan for system growth by having a computer with space for additional HDDs. This makes
it easy to add additional HDDs as the system grows.
Page 25 7EN42-0168-00
IT Guide IT Requirements
NOTE: It is possible to use other RAID configurations, such as RAID 0 or RAID 5. These
configurations are not discussed in this document.
7EN42-0168-00 Page 26
IT Requirements IT Guide
Operating Environment
PME supports the following environments and software:
NOTE: The operating system and SQL Server combination you choose must be supported by
Microsoft. This applies to edition, version, and 32-/64-bit.
** PME includes a free version of SQL Server Express. You have the option to install this Express
version during the installation of PME, if you don't want to use a different SQL Server.
Page 27 7EN42-0168-00
IT Guide IT Requirements
*** You must configure virtual environments with a supported Windows operating system and SQL
Server edition. It is possible to mix virtual and non-virtual environments for PME server and clients.
Windows Updates
Critical and routine Windows Updates can be applied to the operating systems hosting the PME
server and clients without prior approval by Schneider Electric.
Localization
PME supports the following languages:
English, Chinese (Traditional and Simplified), Czech, French, German, Italian, Polish, Portuguese,
Russian, Spanish, and Swedish.
A non-English version of PME only supports an operating system and SQL Server of the same
locale. For example, a Spanish version of the product must be used with a Spanish version of SQL
Server and an operating system with a regional setting of Spanish.
The English version of PME can be used with a supported language, non-English operating system
and SQL Server as long as both have the same locale. For example, an English version of the
product can be used with a German version of SQL Server and an operating system with a regional
setting of German.
l Windows Server can use server-class computer hardware. It can access more CPUs and more
RAM than Windows. For example, Windows 10 is limited to two physical CPUs.
l The SQL Server 64-bit performance is higher than the 32-bit version.
l 32-bit operating systems are limited to just 4 GB of RAM, 64-bit versions are not.
NOTE: The operating system and SQL Server combination you choose must be supported by
Microsoft. This applies to edition, version, and 32/64 bit.
7EN42-0168-00 Page 28
IT Requirements IT Guide
In addition, PME has the following limitations when used with SQL Server Express:
l Only supported for Standalone systems, not for Distributed Database systems.
NOTE: PME includes a free version of SQL Server Express. You have the option to install this
Express version during the installation of PME, if you do not want to use a different SQL Server.
Type Description
PME requires a certain configuration of the
New SQL Server Standard
SQL Server.
PME includes a free version of SQL Server
New SQL Server Express Express. You have the option to install this
Express version during the installation of PME.
To use an existing instance of SQL Server
Standard , the SQL Server setup wizard must
Existing SQL Server Standard
be rerun to configure the software correctly for
use with PME.
The PME installer can add a new instance to
Existing SQL Server Express an existing SQL Server Express for use with
PME.
NOTE: The operating system and SQL Server combination you choose must be supported by
Microsoft. This applies to edition, version, and 32-/64-bit.
Page 29 7EN42-0168-00
IT Guide IT Requirements
PME can be used in a clustered environment when deployed in a Distributed Database architecture.
NOTE: SQL Server clustering is only supported for Distributed Database systems, not for
Standalone systems.
7EN42-0168-00 Page 30
IT Requirements IT Guide
Network Connectivity
Network Communication
The PME server, database server, and clients must be able to communicate with each other over
the network using TCP/IP protocol. The licensing component of PME requires that PME clients and
server can resolve each other’s address by name (not just fully qualified domain name or IP
address). If a proxy server is used on the network, then a local address bypass must be configured
on the PME server.
Network Shares
Engineering Clients require that the Power Monitoring Expert folder on the PME server is shared
with full read and write permissions. File and Printer Sharing must be enabled.
l For Distributed Database installations of PME, the Database Manager tool can only be used if
the database server and the PME application server are in the same domain. The Database
Manager cannot be used, in a distributed database installation, if the database server and the
PME application server are in workgroups.
l A domain account is required for Side-by-Side upgrades of distributed systems using the Con-
figuration Manager Tool. This domain account must be:
A member of the Administrators group on the PME server
Added as a Login in SQL Server with sysadmin role in the database instance.
l PME supports Windows Active Directory services for user account sharing.
IPv6 Compatibility
PME supports IPv6 (and IPv4) for communications with metering devices. The software
components of PME require IPv4. That means PME can be used on computers with single stack
IPv4 or dual stack IPv4/IPv6 network adapters.
IP Port Requirements
PME depends on certain ports for the communication between its components and the connected
devices. Which ports are required for a specific installation depends on the system configuration
and the monitoring devices used.
The following table lists all relevant ports and their functions:
Page 31 7EN42-0168-00
IT Guide IT Requirements
7EN42-0168-00 Page 32
IT Requirements IT Guide
* The direction of a port is determined by the communication initiation request which will establish
the communication socket.
The following image shows the ports and the components they are associated with:
Page 33 7EN42-0168-00
IT Guide IT Requirements
Device Networks
This section provides information on the communication links between the software and the
monitoring devices.
Use the links in the table below to find the content you are looking for:
7EN42-0168-00 Page 34
IT Requirements IT Guide
l Smart panels
l Modbus™ TCP
l Modbus™ RTU
l ION™
l OPC DA
For a device to be compatible with PME, it must support one of these communication protocols.
Page 35 7EN42-0168-00
IT Guide IT Requirements
Network Types
The two basic types of communication networks for PME are Ethernet and serial.
Ethernet Networks
Ethernet device networks can be integrated into regular corporate LANs or they can be separate,
independent networks, providing a higher level of security and availability.
Devices are configured in PME by providing fixed IP addresses (IPv4 or IPv6) and ports, or based
on device names. Device names must be used for devices with dynamic address assignment, for
example using the DHCP protocol. When device names are used in PME, then a form of name
resolution mechanism is required on the network.
Device communications are based on encapsulated Modbus or ION protocol and are not encrypted.
Bandwidth requirements per device are typically low, but depend heavily on the amount and type of
data requested from the device by PME.
Ethernet networks are in many ways superior to serial networks and we recommend that you use
Ethernet networks whenever possible.
NOTE: If you use an ION meter as a gateway, with Ethergate protocol, you loose the ability to
multi-master the serial devices.
Serial device communications are based on Modbus RTU or ION protocol and are not encrypted.
See Tools for information on how to design a serial network.
l The existing Ethernet networks do not allow the connection of monitoring devices.
Ethernet networks are in many ways superior to serial networks and we recommend that you use
Ethernet networks whenever possible.
7EN42-0168-00 Page 36
IT Requirements IT Guide
Network Performance
Communications between the software and the devices consist of :
l On demand, real-time data requests, for example for Diagrams or Dashboards displays.
l Periodic polling and uploading of data logs, events, and waveform records.
To optimize the on demand and background polling performance, consider the following when
designing the system and the communication network:
l Real-time data polling periods should be set to meet the user needs. Do not poll with high speed
when it is not needed. Real-time data clients include Vista, Diagrams, OPC, VIP, Trends, and
EWS.
l Disable devices that are not presently commissioned or functional. This includes devices that
are inoperable, or that have a communication error rate >5%.
l Connect high-end devices with power quality monitoring features, such as the ION9000, dir-
ectly through Ethernet, not serial. These devices can generate large amounts of logged data,
such as power quality data, which requires a high bandwidth connection to the monitoring soft-
ware. If a direct Ethernet connection is not possible, then connect the devices through small
serial loops, with one or two devices per loop.
l Setup the devices to only log those measurements that are needed to meet the user needs.
l Schedule the log uploads to occur at times when the system usage is low, for example during
night time or off hours.
l Use the Daisy Chain Calculator tool to determine the maximum number of devices in a serial
loop for your system. See Tools for more information.
l In most applications, Ethernet networks will provide a better performance than serial networks.
Page 37 7EN42-0168-00
IT Guide IT Requirements
Time synchronization
To maintain accurate time in the monitoring system, the devices must be time synchronized.
Depending on the synchronization mechanism, different levels of time accuracy can be achieved.
PME has the ability to synchronize devices to the PME server computer clock. This can be done
over serial networks and Ethernet networks.
The time synchronization to the computer clock using the regular communications protocols can
maintain a system time accuracy in the range of seconds. This is accurate enough for many
applications. However, for applications such as power event analysis or protection coordination
studies, that require high absolute and relative time accuracy, you need to use other time
synchronization methods for the devices, such as PTP or GPS time synchronization.
7EN42-0168-00 Page 38
IT Requirements IT Guide
Tools
Use the Daisy Chain Calculator tool to design your serial communication networks. This tool helps
you estimate the communication utilization for serial daisy chains. You can use it for new system
design and for optimizing existing systems.
NOTE: The Daisy Chain Calculator is available through the Exchange Community. See
Resources for link information.
Page 39 7EN42-0168-00
IT Guide IT Requirements
Other IT Considerations
PME Server Name Limitations
The computer name for the PME server must have 15 characters or less, and use only letters,
numbers, or the "_" (underscore) character.
NOTE: The computer name must not be changed after the PME software is installed. If the
computer name is changed after the install, the software ceases to function correctly. Should this
occur, contact Technical Support for assistance.
Display Resolution
The minimum display resolution for PME user interfaces is 1024 x 768 pixels.
7EN42-0168-00 Page 40
Cybersecurity IT Guide
Cybersecurity
The information in this section is organized by the following life-cycle stages:
l Planning
l Configuration
l Operation
l Administration
Planning
Network security
PME is designed for an intranet environment within a secured network infrastructure. PME is NOT
designed for direct Internet connection.
Data encryption
At Rest
PME protects the passwords of its user accounts, as well as the Windows and SQL Server
accounts using SHA-256 and AES-256 cryptography. PME uses a unique encryption key for each
installation. The key is generated during the installation of PME. The PME installer offers
functionality for exporting/importing encryption keys for the installation of PME clients or system
upgrades.
The power monitoring data that is collected by PME, and system configuration data are not
encrypted.
In Transit
PME uses Transport Layer Security (TLS) 1.2 for an encrypted, authenticated connection using
HTTPS between the server and the Web clients. Both self-signed and authority issued certificates
are supported. PME is installed with a self-signed certificate and a self-signed certificate is
configured automatically. We recommend that you replace this with a security certificates from a
Certificate Authority (CA).
The communication between PME and connected monitoring devices is not encrypted.
Malware detection
PME can be used with antivirus (AV) software. AV software can have a significant impact on
system performance if not set up correctly. In particular, SQL Server performance can be affected if
data and log files are not excluded from on-access scans. We have seen issues during the
installation of PME, where AV scan delays caused timeouts and failures in the installation process.
PME can be used with whitelisting software products such as McAfee Applicaton Control software.
See Application control (whitelisting) software for more information.
Page 41 7EN42-0168-00
IT Guide Cybersecurity
NOTE: Special configuration of the AV and whitelisting software might be required. Follow the
instructions of the software vendor for installing, configuring, and operating the AV and whitelisting
software.
PME Users
A user account in PME provides access to the system. There are 3 different types of users -
standard users, Windows users, and Windows groups. Each user has an access level, which
determines the actions the user is allowed to perform in PME. There are no pre-configured user
accounts or user groups in the system. One supervisor account is created with a user defined
password during the installation of the software. Additional user accounts and groups must be
created manually after installation. PME supports Windows Active Directory integration for
Windows users and groups.
TIP: Use Windows users and groups to take advantage of Windows account security features
such as maximum login attempts or minimum password requirements.
If PME is configured to use SQL Integrated Authentication, then an additional Windows account is
required for database access. This Windows account is also used to run the PME services and the
IIS Application Pools. This account must be created manually and account details must be provided
during the installation of the software.
If SQL Server Express is installed, with Mixed Mode authentication, through the PME installer, a sa
account with a unique, default password is created automatically during install. The password can
be changed at any time through SQL Server Management Studio.
7EN42-0168-00 Page 42
Cybersecurity IT Guide
PME Services
PME uses a number of services to perform the background server tasks. The services use the
Local System account, or the Windows account used for SQL Integrated Authentication if that is
configured.
Hardware Ports
Computer ports and inputs, such as USB ports or DVD drives are not required for PME to function
correctly. These inputs can be permanently disabled if necessary. The same applies to the AutoRun
and AutoPlay functionality which can also be disabled without affecting the operation of the
software.
2. Select Disable in the dropdown list and click Save to apply the change.
l Operating system version and type (32- or 64-bit) l Device type count
l City or region
l Screen DPI
Page 43 7EN42-0168-00
IT Guide Cybersecurity
The diagnostics and usage service collects and sends data to Schneider Electric weekly on
Monday at 2:00 a.m. (server time), over HTTPS at port 443. Each time the service runs, it creates a
log file in the system\bin folder in the Power Monitoring Expert install location.
NOTE: All diagnostics and usage data is sent to Schneider Electric anonymously. None of the
collected information identifies you or your company. For more information on Schneider Electrics
Privacy Policy, see the Schneider Data Privacy and Cookie Policy. See Resources for link
information.
Network Shares
PME Engineering Clients require that the Power Monitoring Expert folder on the PME server is
shared with full read and write permissions. File and Printer Sharing must be enabled as well.
As long as the PME server has the original key stored securely in the registry it is possible to export
a copy at any time using the installer. However, should the original key get deleted from the server
somehow, it cannot be recreated or exported. Keep the exported system key in a safe location,
protected from unauthorized access.
Change the product directory's share permission to Read/Write for users of Engineering Client
computers who need to modify files, such as Vista diagrams.
Configuration
Configure PME users and user groups
There are no pre-configured user accounts or user groups in a newly installed system. One
supervisor account was created, with a user defined password, during the installation of the
software. Create additional user accounts and groups after installation. PME supports Windows
users and groups for integration with Windows and Active Directory.
For information on creating users and user groups, and on setting user access levels, see User
Manager help.
7EN42-0168-00 Page 44
Cybersecurity IT Guide
When you deploy Application Control to protect a system, it scans the system and creates a
whitelist of all executable binaries and scripts present on the system. The whitelist also includes
hidden files and folders.
The whitelist lists all authorized files and determines trusted or known files. In Enabled mode, only
files that are present in the whitelist can execute. All files in the whitelist are protected and cannot
be changed or deleted. An executable binary or script that is not in the whitelist is said to be
unauthorized and is prevented from running.
Consider the following when using application control software with PME:
l Complete the system configuration before before setting up and enabling application control
software.
l Any program or script that should be able to update the system will need to be configured as an
updater.
l Disable Application Control to make changes to the system. Enable it again after the change.
Operation
Session timeout
PME automatically times out inactive client sessions. Web Applications clients are logged out and
Windows application clients (Vista, Designer, Management Console) are locked after a period of
inactivity. The timeout period is configurable, it is set to 20 minutes by default. See Configuring
session timeout settings for details.
To restart or unlock the session you must enter the login credentials. A session is considered
inactive, if none of the following actions are detected:
l Mouse movement
l Mouse click
l Keyboard activity
NOTE: If custom content links are added to the Web Applications framework, then the custom
content must either implement the idle detection, or activity on that content is not registered and
the Web client session can time out unexpectedly. See Adding idle detection to custom Web
Application links for details.
Page 45 7EN42-0168-00
IT Guide Cybersecurity
Administration
Windows and SQL Server Updates
Critical and routine Windows and SQL Server updates can be applied to the operating systems
hosting the PME server and clients without prior approval by Schneider Electric.
7EN42-0168-00 Page 46
Reference IT Guide
Reference
Use the links below to find the content you are looking for:
Page 47 7EN42-0168-00
IT Guide Reference
* This account is only created on standalone servers where the SQL Server software and PME are
installed on the same computer.
For installations using SQL Integrated Authentication, the following additional accounts and
permissions are required.:
7EN42-0168-00 Page 48
Reference IT Guide
- Needs to be a member
Account used of local Administrators
for group - Manually created by the user.
SQL Integrated - Needs 'Log on as a - Used by PME to access the SQL server databases.
Authentication service' privilege on
application server
This is not an additional user account. It is just an
Login used to added requirement for the Logins used to access the
access PME Needs sysadmin server Engineering Client applications (Vista, Designer,
Engineering role for the PME Management Console, Management Console tools).
Client databases.
applications The PME databases are: ApplicationModules, ION_
Data, ION_Network, ION_Systemlog
NOTE: When PME is installed with SQL Integrated Authentication, then the Windows account
that is used to access the database, is also used to run the PME services and the IIS Application
Pools.
Page 49 7EN42-0168-00
IT Guide Reference
Server
Login Authentication Database Membership
Role
AMUser SQL Public ApplicationModules AMApplicationRole
ApplicationModules db_owner
ION_Data db_owner
ION_Network db_owner
ION SQL Public ION_SystemLog db_owner
SQLAgentOperatorRole,
msdb * SQLAgentReader Role, SQL
AgentUserRole
ION_Data ION_DSD_Reader
ionedsd SQL Public
ION_Network NOM_DSD_Reader
db_backupoperator, db_
ApplicationModules
ddladmin, Maintenance
db_backupoperator, db_
ION_Data
ddladmin, Maintenance
IONMaintenance** Windows Public
db_backupoperator, db_
ION_Network
ddladmin, Maintenance
db_backupoperator, db_
ION_SystemLog
ddladmin, Maintenance
Server
Login Authentication Database Membership
Role
ApplicationModules db_owner
ION_Data db_owner
Account used for ION_Network db_owner
SQL Integrated Windows Public ION_SystemLog db_owner
Authentication SQLAgentOperatorRole,
msdb* SQLAgentReader Role,
SQL AgentUserRole
7EN42-0168-00 Page 50
Reference IT Guide
db_backupoperator, db_
ApplicationModules
ddladmin, Maintenance
db_backupoperator, db_
ION_Data
ddladmin, Maintenance
IONMaintenance ** Windows Public
db_backupoperator, db_
ION_Networks
ddladmin, Maintenance
db_backupoperator, db_
ION_SystemLog
ddladmin, Maintenance
NOTE: When PME is installed with SQL Integrated Authentication, then the Windows account
that is used to access the database, is also used to run the PME services and the IIS Application
Pools.
Other
PME must have access to the master and tempdb System Databases.
The PME Database Manager tool requires that the Windows account that is used to run it has
sysadmin permissions on the PME SQL Server instance. The Database Manager is an optional
tool, used for managing the PME databases.
Page 51 7EN42-0168-00
IT Guide Reference
Startup Log on
Service Name Description
type Account
Receives and processes
high-priority alarm and
event notifications
coming from modem
connected meters on
remote power monitoring
locations. When this
Local
ION Alert Monitor Manual happens, the Alert
System *
Monitor initiates a
communications
connection to the remote
modem site to download
additional logged data
(for example, data,
events, and waveforms).
Allows the Event
Notification Module
(ENM) to read alarms
ION Application directly from the ION_
Local
Modules Alarm Manual Data database.
System *
Services Host Starts on demand from
other services (for
example, from the Event
Notification Module).
Hosts common web
ION Application
Local services used by the
Modules Core Automatic
System * Web Applications
Services Host
component.
Hosts web services that
provide low-level access
to system data (that is,
ION Application
Local real-time, historical,
Modules Data Automatic
System * alarming, and
Services Host
authentication) for the
Web Applications
component.
7EN42-0168-00 Page 52
Reference IT Guide
Page 53 7EN42-0168-00
IT Guide Reference
7EN42-0168-00 Page 54
Reference IT Guide
Page 55 7EN42-0168-00
IT Guide Reference
Runs Reports
subscriptions according
Automatic to user-defined
ION Report Local
(Delayed schedules.
Subscription Service System *
Start)
Starts several minutes
after the server starts.
Manages
communication links to
and from the product.
ION Site Service is
responsible for handling
packet communications
to system devices and
controlling direct device
communications. The
Local
ION Site Service Automatic service reacts to
System *
changes in network
configuration: for
example, changes to
certain channels,
configuration
parameters, ports, or
device parameters can
often interrupt a
connection.
Performs evaluations
Automatic
ION Software Data Local based on real time data
(Delayed
Processing Service System * from the power
Start)
monitoring system.
Enables software data
services via
ModbusTCP/IP, and is
ION Software
Local treated like a device in
Modbus Gateway Manual
System * Management Console.
Service
For example, the Circuit
Breaker Aging Service
uses this service.
Provides aggregation,
ION Virtual control, and
Local
Processor Service - Automatic mathematical analysis of
System *
[Link] power monitoring
system data.
7EN42-0168-00 Page 56
Reference IT Guide
Page 57 7EN42-0168-00
IT Guide Reference
* When PME is installed with SQL Integrated Authentication, then the Windows account that is
used to access the database, is also used to run the PME services, instead of the Local System
account.
** This service only exists on systems with SQL Server, not SQL Server Express.
7EN42-0168-00 Page 58
Reference IT Guide
Hierarchy Manager
Application Modules App
Local System * Slideshow
Pool
System Data Service
Trends
Web
Alarm Configuration
ION ION/diagrams
ION App Pool Local System *
ION Report Data Service
Web Services
Rate Editor
Web Reporter App Pool Local System *
Reporter
* When PME is installed with SQL Integrated Authentication, then the Windows account that is
used to access the database, is also used to run the IIS Application Pools, instead of the Local
System account.
Page 59 7EN42-0168-00
IT Guide Reference
Databases
PME Databases
Power Monitoring Expert (PME) uses four databases to store device communication parameters,
system configuration settings, and logged historical data.
ION_Network database
Sometimes called the NOM (Network Object Model), the ION_Network database stores device
information, such as, device name, device type and connection address (for example, IP address
and TCP/IP port or device/Modbus ID). It also contains information about the optional Application
Module settings, other ION Servers, Sites, Dial Out Modems, and Connection Schedules. There is
only one ION_Network per system.
ION_Data database
The ION_Data database contains the historical data, events and waveforms from devices
connected to the system. This includes: onboard logging configured on devices; and, PC-based
logging configured in the device translators and the Virtual Processors.
l Plus many other Warnings and Errors relating to PME system functions.
7EN42-0168-00 Page 60
Reference IT Guide
Reports:
l Energy by IT Customer
Page 61 7EN42-0168-00
IT Guide Reference
Example
NOTE: Use the Database Growth Calculator tool to estimate the database growth for your
system. The tool is available through the Exchange Community. See Resources for link
information.
The following shows the database growth estimate for logging of a single measurement every 15
minutes:
NOTE: Use the Database Growth Calculator tool to estimate the database growth for your
system. The tool is available through the Exchange Community. See Resources for link
information.
7EN42-0168-00 Page 62
Reference IT Guide
NOTE: Use the Database Growth Calculator tool to estimate the database growth for your
system. The tool is available through the Exchange Community. See Resources for link
information.
Page 63 7EN42-0168-00
IT Guide Reference
2. On the Session Timeout Settings page, enter the timeout period for Web clients and Windows
clients.
3. Click Save.
Related Topic:
7EN42-0168-00 Page 64
Reference IT Guide
Prerequisite: The custom application must be in the same Application Pool as the regular PME
applications, and must use the same authentication configuration.
NOTE: If you want your application to take part in keeping PME non-idle, but you do not want
your application to log itself out after the idle period, you can add the following JSON as a
parameter to the idle() method: {enableLogoutRedirection: false;}
Page 65 7EN42-0168-00
IT Guide Reference
Related Topic:
7EN42-0168-00 Page 66
Schneider Electric
35 rue Joseph Monier
92500 Rueil Malmaison – France
7EN42-0168-00 09/2018
TLS 1.2 is crucial in PME for securing communications between the server and Web clients by providing encrypted and authenticated connections using HTTPS. This security measure ensures data integrity and confidentiality during transmission, protecting against potential eavesdropping or tampering in an intranet environment. The use of TLS 1.2 also allows PME to support both self-signed and authority-issued certificates, recommending the use of CA-issued certificates for enhanced security .
Ensuring network security and compatibility in a PME distributed database environment involves several steps: enabling full read and write permissions for Engineering Clients on shared PME server folders, configuring network communication over TCP/IP protocols, ensuring domain membership for side-by-side upgrades as the database manager tool requires domain accounts, and configuring local address bypassing if a proxy server is used. Additionally, PME should be installed in secured intranet environments as it is not designed for direct internet connection .
The ION Application Modules Alarm Services Host allows the Event Notification Module (ENM) to read alarms directly from the ION_Data database. It is started on demand by other services and plays a crucial role in managing and processing alarm and event notifications within the PME system. This service ensures that high-priority alarms are given attention by directly interfacing with the event data for real-time monitoring and action .
Antivirus software should be specially configured to avoid scanning PME's data and log files on SQL Servers. Incorrect configuration can significantly impact system performance, leading to SQL Server performance degradation and possible installation timeouts or failures for PME. Proper configuration involves excluding PME's data and log files from on-access scans, as recommended by Microsoft, to ensure system stability and performance .
PME uses SHA-256 and AES-256 cryptography to protect user account passwords and SQL Server accounts at rest. A unique encryption key is generated during PME installation. For data in transit, PME employs Transport Layer Security (TLS) 1.2 to secure communication using HTTPS between servers and Web clients. While the system is designed for intranet environments and not direct internet connection, PME does not encrypt power monitoring and system configuration data. This encryption approach emphasizes cybersecurity within a secure network while pointing out the areas not covered by encryption .
The ION Log Inserter Service is essential for historical data collection in PME, gathering data from devices and the Virtual Processor, then storing it in the ION_Data database. This service ensures that PME can efficiently process and archive historical data necessary for power monitoring analysis, supporting accurate record-keeping and retrieval for performance evaluations and troubleshooting .
The PME server name must have 15 characters or less and use only letters, numbers, or the underscore character. Changing the server name post-installation will result in the software becoming non-functional, necessitating technical support intervention. Additionally, all PME user interfaces require a minimum display resolution of 1024 x 768 pixels to function correctly .
Using whitelisting software like McAfee Application Control with PME requires careful configuration to prevent interference with system operations. Such software should be set to allow essential PME processes, as incorrect settings can negatively impact system performance by blocking critical functions. Whitelisting is particularly effective in enhancing security by ensuring only approved applications run, protecting against unauthorized software execution that could compromise system integrity .
Changing the computer name on which PME is installed causes the software to cease functioning correctly because the system is bound to the original name for operations. To mitigate this, it is critical not to alter the computer name post-installation. If a change is made inadvertently, technical support should be contacted to assist in resolving the issue, as the software relies on this configuration to maintain consistent network and component identity .
Using SQL Server clustering for PME increases system availability by allowing multiple SQL Servers to work together as a single entity. Clustering is supported only for Distributed Database systems in PME, where the SQL Server component must be deployed in the clustered environment, while the Application Server remains in a non-clustered environment. It is important to ensure that the operating system and SQL Server combination is supported by Microsoft .